{"id":15242,"date":"2026-05-30T03:52:54","date_gmt":"2026-05-30T03:52:54","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15242"},"modified":"2026-05-30T03:52:54","modified_gmt":"2026-05-30T03:52:54","slug":"ransomware-abuses-system-activity-to-encrypt-drives-with-elevated-privileges","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15242","title":{"rendered":"Ransomware Abuses SYSTEM Activity to Encrypt Drives with Elevated Privileges"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A newly analyzed ransomware pressure, \u201cThe Gents,\u201d is elevating concern amongst safety researchers because of its skill to mix robust encryption with aggressive lateral motion. <\/p>\n<p class=\"wp-block-paragraph\">What makes this menace notably harmful is its use of SYSTEM-level scheduled duties to encrypt native drives, permitting attackers to function with the best<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/gentlemen-ransomware-operation\/\" type=\"post\" id=\"186639\" target=\"_blank\" rel=\"noreferrer noopener\"> Home windows methods privileges<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">This method ensures deeper system entry, improves encryption reliability, and bypasses many commonplace user-level restrictions.<\/p>\n<p class=\"wp-block-paragraph\">The Gents ransomware makes use of command-line arguments to regulate its execution. A key characteristic is the \u201c\u2013full\u201d mode, which launches two parallel processes: one concentrating on native drives utilizing the \u201c\u2013system\u201d flag and one other concentrating on community shares with the \u201c\u2013shares\u201d flag. <\/p>\n<p class=\"wp-block-paragraph\">When the system mode is triggered, the malware creates a scheduled process that re-executes itself below the SYSTEM account.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/05\/image-132.webp\" alt=\"Encryption mode command-line arguments (Source : Microsoft).\"\/><figcaption class=\"wp-element-caption\"><em>Encryption mode command-line arguments<\/em> (Supply : Microsoft).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Earlier than encryption begins, the ransomware disables Microsoft Defender, deletes shadow copies, clears occasion logs, and removes forensic artifacts corresponding to PowerShell historical past. These steps considerably cut back detection and restoration choices. <\/p>\n<p class=\"wp-block-paragraph\">This method offers the ransomware unrestricted entry to information which will in any other case be locked or protected. The malware first deletes any current scheduled process named \u201cgentlemen_system,\u201d then creates a brand new one configured to run with elevated privileges, and at last executes it instantly. This chain ensures clear execution and avoids conflicts.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/28\/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Tracked by Microsoft as Storm-2697<\/a>, this ransomware-as-a-service (RaaS) operation has developed quickly since mid-2025 and is now being utilized in widespread assaults throughout a number of industries worldwide.<\/p>\n<p class=\"wp-block-paragraph\">From a cryptographic perspective, The Gents makes use of a hybrid mannequin combining Curve25519 elliptic-curve cryptography with the XChaCha20 stream cipher. <\/p>\n<p class=\"wp-block-paragraph\">Every file is encrypted utilizing a novel ephemeral key, guaranteeing robust isolation between information. Smaller information are absolutely encrypted, whereas bigger information are partially encrypted in a number of chunks to extend velocity whereas nonetheless rendering them unusable.<\/p>\n<h2 id=\"h-ransomware-abuses-system-task\" class=\"wp-block-heading\"><strong>Ransomware Abuses SYSTEM Activity<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Past encryption, The <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/gentlemen-ransomware-2\/\" type=\"post\" id=\"169552\" target=\"_blank\" rel=\"noreferrer noopener\">Gents ransomware assault<\/a> stands out for its extremely aggressive self-propagation capabilities. When the \u201c\u2013unfold\u201d choice is used, the malware makes an attempt to maneuver laterally throughout the community utilizing a number of strategies concurrently, together with PsExec, WMI, scheduled duties, companies, and PowerShell remoting.<\/p>\n<p class=\"wp-block-paragraph\">The velocity arguments (<code>--<\/code>quick,\u00a0<code>--<\/code>superfast,\u00a0<code>--<\/code>ultrafast) are mutually unique and management how a lot of every giant file is encrypted.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/05\/image-170.webp\" alt=\"The Gentlemen ransomware\u2019s usage prompt (Source : Microsoft).\"\/><figcaption class=\"wp-element-caption\"><em>\u00a0The Gents ransomware\u2019s utilization immediate<\/em> (Supply : Microsoft).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The malware prepares contaminated methods as distribution factors by creating hidden SMB shares and enabling nameless entry. It then scans for different machines and makes an attempt as much as 21 completely different execution strategies per goal. <\/p>\n<p class=\"wp-block-paragraph\">This redundancy ensures that even when some strategies fail, others might succeed, considerably rising the possibility of widespread compromise.<\/p>\n<p class=\"wp-block-paragraph\">Generates a novel ephemeral Curve25519 key pair, consisting of a randomly generated non-public key and its corresponding public key.<\/p>\n<p class=\"wp-block-paragraph\">Moreover, the ransomware employs double extortion techniques. It not solely encrypts information but additionally exfiltrates delicate information, threatening to leak it publicly if the ransom shouldn&#8217;t be paid. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/05\/image-156.webp\" alt=\"&#10;The Gentlemen ransomware\u2019s file encryption mechanism (Source : Microsoft).\"\/><figcaption class=\"wp-element-caption\"><em>The Gents ransomware\u2019s file encryption mechanism<\/em> (Supply : Microsoft).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">This will increase stress on victims, particularly in sectors like healthcare, finance, and schooling, the place information sensitivity is excessive.<\/p>\n<p class=\"wp-block-paragraph\">Persistence is maintained by each scheduled duties and registry run keys, permitting the malware to outlive reboots and proceed operations. In some circumstances, it additionally wipes free disk house to stop restoration of deleted information, additional complicating incident response.<\/p>\n<p class=\"wp-block-paragraph\">The mix of SYSTEM-level execution, robust encryption, and multi-method propagation makes The Gents a extremely efficient and harmful ransomware menace. <\/p>\n<p class=\"wp-block-paragraph\">Its rising adoption by underground boards means that organizations ought to anticipate elevated exercise and may prioritize detection of scheduled process abuse, privilege escalation, and strange lateral motion patterns.<\/p>\n<h2 id=\"h-indicators-of-compromise\" class=\"wp-block-heading\"><strong>Indicators of compromise<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Kind<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67<\/td>\n<td>SHA-256<\/td>\n<td>Gents ransomware encryptor<\/td>\n<\/tr>\n<tr>\n<td>078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b<\/td>\n<td>SHA-256<\/td>\n<td>PsExec binary<\/td>\n<\/tr>\n<tr>\n<td>fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68<\/td>\n<td>SHA-256<\/td>\n<td>Gents wallpaper Bitmap file<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Notice:<\/strong>\u00a0IP addresses and domains are deliberately defanged (e.g.,\u00a0<code>[.]<\/code>) to stop unintentional decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms corresponding to MISP, VirusTotal, or your SIEM.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Comply with us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get On the spot Updates and Set GBH as a Most popular Supply in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A newly analyzed ransomware pressure, \u201cThe Gents,\u201d is elevating concern amongst safety researchers because of its skill to mix robust encryption with aggressive lateral motion. What makes this menace notably harmful is its use of SYSTEM-level scheduled duties to encrypt native drives, permitting attackers to function with the best Home windows methods privileges. This method [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15244,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2455,2144,9052,1124,374,500,849,5296],"class_list":["post-15242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-abuses","tag-drives","tag-elevated","tag-encrypt","tag-privileges","tag-ransomware","tag-system","tag-task"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15242"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15242\/revisions"}],"predecessor-version":[{"id":15243,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15242\/revisions\/15243"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15244"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-30 18:03:54 UTC -->